What auditors expect to see, explained: the fifteen explicitly required documents with clause references, and the supporting set a small business realistically needs.
ISO/IEC 27001:2022 explicitly requires roughly fifteen documented items. Everything else that swells an ISMS to a hundred documents is either supporting material for Annex A controls or consultant habit. This guide lists what is actually mandatory, clause by clause, then the documents auditors expect even though the standard does not name them.
| Document / record | Clause | Notes |
|---|---|---|
| Scope of the ISMS | 4.3 | What is in and out, and why exclusions are justified |
| Information security policy | 5.2 | Approved by top management, communicated, available |
| Risk assessment process | 6.1.2 | How you identify, analyse and evaluate risk, consistently |
| Risk treatment process and plan | 6.1.3 | How treatment decisions are made and tracked |
| Statement of Applicability | 6.1.3 d) | All 93 Annex A controls: applicable or not, justified, status |
| Information security objectives | 6.2 | Measurable, monitored, updated |
| Evidence of competence | 7.2 | Training records, CVs, certifications for security roles |
| Documented information the ISMS requires | 7.5 | Version control, approval and availability of the above |
| Operational planning and control records | 8.1 | Evidence processes ran as planned |
| Risk assessment results | 8.2 | Your completed risk register, at planned intervals |
| Risk treatment results | 8.3 | Treatment actions and their outcomes |
| Monitoring and measurement results | 9.1 | Security metrics and their evaluation |
| Internal audit programme and results | 9.2 | Plan, reports, findings |
| Management review results | 9.3 | Minutes covering all required inputs and decisions |
| Nonconformities and corrective actions | 10.1 | What went wrong, cause, action, effectiveness check |
Annex A controls repeatedly use the phrase “should be defined” and auditors interpret several of them as needing documents. For a typical UK small business the expected set is:
We publish free, no-email-required templates for the registers above: the risk register, Statement of Applicability, evidence tracker, internal audit checklist and supplier review register.
Around fifteen explicitly required items, listed above with clause references. Supporting Annex A documentation typically takes a small business to 20-30 documents in total.
No single published list; the requirements are spread through clauses 4-10. This guide consolidates them with the clause references auditors check against.
No format is mandated, but version-controlled documents with owners, approval and review dates are the accepted evidence, and in practice most UK small businesses maintain them as Word documents.
ISOvault is the controlled home for exactly this document set: versioning, approval with a named approver, review reminders and Word export. 14 days free, no card required.